Vulnerabilidades em HCL Software

334 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2024-23551MEDIUMHCL BigFix Compliance is potentially affected by Oracle database credentials stored at endpointEPSS 0.2%CVE-2024-42188LOWHCL Connections is vulnerable to a broken access control vulnerabilityEPSS 0.2%CVE-2023-37537HIGHHCL AppScan Presence deployed as Windows service might be vulnerable to an Unquoted Service Path vulnerabilityEPSS 0.2%CVE-2025-55249LOWHCL AION is affected by a Missing Security Response Headers vulnerability.EPSS 0.2%CVE-2025-55278HIGHHCL DevOps Loop is susceptible to an improper authentication vulnerabilityEPSS 0.2%CVE-2024-30146MEDIUMHCL Domino Leap is affected by improper access controlEPSS 0.2%CVE-2024-30149MEDIUMHCL AppScan Source is affected by an expired TLS/SSL certificateEPSS 0.2%CVE-2025-31994MEDIUMHCL Unica Campaign is vulnerable to Reflected Cross-Site Scripting (XSS)EPSS 0.2%CVE-2023-37513LOWHCL Traveler To Do is vulnerable to revealing sensitive information via the task switcherEPSS 0.2%CVE-2024-42178LOWHCL MyXalytics is affected by a failure to restrict URL access vulnerabilityEPSS 0.2%CVE-2024-30124MEDIUMHCL Sametime is impacted by insecure servicesEPSS 0.2%CVE-2023-37512LOWHCL Traveler Companion is vulnerable to revealing sensitive information via the task switcherEPSS 0.2%CVE-2025-55254LOWHCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI)EPSS 0.2%CVE-2025-31954MEDIUMHCL iAutomate is susceptible to a sensitive information disclosureEPSS 0.2%CVE-2025-31976MEDIUMHCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentialsEPSS 0.2%CVE-2025-52654MEDIUMHCL MyXalytics is affected by an HTML InjectionEPSS 0.2%CVE-2023-45702MEDIUMHCL Launch Agent as a Windows service is vulnerable to a Denial of ServiceEPSS 0.2%CVE-2023-37540LOWHCL Sametime Chat is affected by an unimplemented feature in the UI EPSS 0.2%CVE-2025-62329MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerabilityEPSS 0.2%CVE-2025-31992MEDIUMHCL MaxAI Assistant is susceptible to a HTML injection vulnerabilityEPSS 0.2%